<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD Firepower 2110 Version 6.6.1 not passing traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175297#M1075286</link>
    <description>&lt;P&gt;Hey, Rob Thank you for responding,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using FDM or FMC to manage this device? FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you ping the internet from the FTD itself? Yes I can Ping 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have NAT configured correctly for outbound traffic from the inside network(s)? Provide the output of "show nat detail".&lt;/P&gt;&lt;P&gt;&amp;gt; show nat detail&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (Inside) to (Outside) source static any interface destination static interface outside2&lt;BR /&gt;translate_hits = 8, untranslate_hits = 8&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 64.16.28.11/27&lt;BR /&gt;Destination - Origin: 10.20.50.1/24, Translated: 64.16.28.11/3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How have you configured your Access Control Policy (ACP)?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 18:44:23 GMT</pubDate>
    <dc:creator>jdelgado</dc:creator>
    <dc:date>2020-10-28T18:44:23Z</dc:date>
    <item>
      <title>FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4174696#M1075258</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Firepower 2110, which is not passing traffice from the Inside interface to the Outside interface. I have run the packet tracer tool and it states that traffic should be passing normally. I have a static route. I am new to Firepower, and I think the issue may be related to the security levels. but unsure. I have been using pinging as a test and I have been trying to get to webpages also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Public IP is redacted. But below is the Show Route and Show Run Interfaces output. Also attached is diagram of the issue. Please any and all help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt;D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;E1 - OSPF external type 1, E2 - OSPF external type 2, V - VPN&lt;BR /&gt;i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt;ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt;o - ODR, P - periodic downloaded static route, + - replicated route&lt;BR /&gt;SI - Static InterVRF&lt;BR /&gt;Gateway of last resort is *.*.28.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;S* 0.0.0.0 0.0.0.0 [1/0] via (*).(*).28.1, Outside&lt;BR /&gt;C 10.20.50.0 255.255.255.0 is directly connected, Inside&lt;BR /&gt;L 10.20.50.1 255.255.255.255 is directly connected, Inside&lt;BR /&gt;C (*).(*).28.0 255.255.255.224 is directly connected, Outside&lt;BR /&gt;L (*).(*).28.11 255.255.255.255 is directly connected, Outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet1/1&lt;BR /&gt;nameif Outside&lt;BR /&gt;cts manual&lt;BR /&gt;propagate sgt preserve-untag&lt;BR /&gt;policy static sgt disabled trusted&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address (*).(*).28.11 255.255.255.224&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/2&lt;BR /&gt;nameif Inside&lt;BR /&gt;cts manual&lt;BR /&gt;propagate sgt preserve-untag&lt;BR /&gt;policy static sgt disabled trusted&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 10.20.50.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 23:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4174696#M1075258</guid>
      <dc:creator>jdelgado</dc:creator>
      <dc:date>2020-10-27T23:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4174822#M1075270</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1117082"&gt;@jdelgado&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using FDM or FMC to manage this device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you ping the internet from the FTD itself?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have NAT configured correctly for outbound traffic from the inside network(s)? Provide the output of "show nat detail".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How have you configured your Access Control Policy (ACP)? Please provide a screenshot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Provide the output of packet-tracer so we can analyse.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 08:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4174822#M1075270</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-28T08:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175297#M1075286</link>
      <description>&lt;P&gt;Hey, Rob Thank you for responding,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using FDM or FMC to manage this device? FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you ping the internet from the FTD itself? Yes I can Ping 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have NAT configured correctly for outbound traffic from the inside network(s)? Provide the output of "show nat detail".&lt;/P&gt;&lt;P&gt;&amp;gt; show nat detail&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (Inside) to (Outside) source static any interface destination static interface outside2&lt;BR /&gt;translate_hits = 8, untranslate_hits = 8&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 64.16.28.11/27&lt;BR /&gt;Destination - Origin: 10.20.50.1/24, Translated: 64.16.28.11/3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How have you configured your Access Control Policy (ACP)?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 18:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175297#M1075286</guid>
      <dc:creator>jdelgado</dc:creator>
      <dc:date>2020-10-28T18:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175353#M1075287</link>
      <description>&lt;P&gt;Try please to remove that NAT rule and replace it with:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) after-auto source dynamic any interface&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175353#M1075287</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-28T19:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175369#M1075290</link>
      <description>&lt;P&gt;I know how to apply the command in an ASA but how would I apply it in the FMC?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175369#M1075290</guid>
      <dc:creator>jdelgado</dc:creator>
      <dc:date>2020-10-28T19:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175382#M1075292</link>
      <description>&lt;P&gt;My bad, apologies, for some reason I had ASA in mind! In the NAT section, add a new rule:&lt;/P&gt;&lt;P&gt;NAT Rule: Auto NAT Rule&lt;/P&gt;&lt;P&gt;Type: Dynamic&lt;/P&gt;&lt;P&gt;Interface Objects: Src (Inside), Dst (Outside)&lt;/P&gt;&lt;P&gt;Translation - Original Source: Select your internal LAN object from the list, if you don't have it, click on the + button to add one&lt;/P&gt;&lt;P&gt;Translation - Translated Source: Destination Interface IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175382#M1075292</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-28T19:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Firepower 2110 Version 6.6.1 not passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175397#M1075293</link>
      <description>&lt;P&gt;It works!! Thank you, Thank You&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 20:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-firepower-2110-version-6-6-1-not-passing-traffic/m-p/4175397#M1075293</guid>
      <dc:creator>jdelgado</dc:creator>
      <dc:date>2020-10-28T20:14:56Z</dc:date>
    </item>
  </channel>
</rss>

